Eight roles govern the platform. Permissions are least-privilege by default; the Vendor role is externally isolated (FR-305) and the Auditor role is strictly read-only (FR-301).
{{ r.initial }}
{{ r.name }}
{{ r.tagline }}
{{ r.note }}
{{ p.mark }} {{ p.label }}